2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19429 | CRITICAL | 9.4 | — | Aug 10, 2026 | Jenkins FilePath.untarFrom() does not validate symlink targets in extracted TAR archives, even in versions patched for C... |
| CVE-2026-13206 | CRITICAL | 9.8 | — | Aug 10, 2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networ... |
| CVE-2026-72593 | CRITICAL | 9.8 | — | Aug 10, 2026 | A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to acce... |
| CVE-2026-72592 | CRITICAL | 9.8 | — | Aug 10, 2026 | An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to e... |
| CVE-2026-72590 | CRITICAL | 9.8 | — | Aug 10, 2026 | An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker... |
| CVE-2026-72589 | CRITICAL | 9.8 | — | Aug 10, 2026 | An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker... |
| CVE-2026-72580 | CRITICAL | 9.8 | — | Aug 10, 2026 | An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute a... |
| CVE-2026-72577 | CRITICAL | 9.8 | — | Aug 10, 2026 | Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary ... |
| CVE-2026-72575 | CRITICAL | 9.1 | — | Aug 10, 2026 | An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, crea... |
| CVE-2026-72569 | CRITICAL | 9.1 | — | Aug 10, 2026 | A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to d... |
| CVE-2026-72567 | CRITICAL | 9.8 | — | Aug 10, 2026 | An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated rem... |
| CVE-2026-72565 | CRITICAL | 9.8 | — | Aug 10, 2026 | A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-tab... |
| CVE-2026-72564 | CRITICAL | 9.6 | — | Aug 10, 2026 | An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to aut... |
| CVE-2026-55799 | CRITICAL | 9.8 | 0.3% | Aug 10, 2026 | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgra... |
| CVE-2026-44416 | CRITICAL | 9.8 | 0.6% | Aug 10, 2026 | Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. U... |
| CVE-2026-42537 | CRITICAL | 9.8 | 0.4% | Aug 10, 2026 | Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0... |
| CVE-2026-40920 | CRITICAL | 9.8 | 0.2% | Aug 10, 2026 | Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade... |
| CVE-2026-32227 | CRITICAL | 9.8 | 0.2% | Aug 10, 2026 | SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to v... |
| CVE-2026-28672 | CRITICAL | 9.8 | 1.0% | Aug 10, 2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. Thi... |
| CVE-2026-66915 | CRITICAL | 10 | 0.6% | Aug 10, 2026 | Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute ar... |
| CVE-2026-19053 | CRITICAL | 9.1 | 0.2% | Aug 10, 2026 | The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQ... |
| CVE-2026-16299 | CRITICAL | 9.8 | 0.1% | Aug 10, 2026 | The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing u... |
| CVE-2026-16298 | CRITICAL | 9.8 | 0.1% | Aug 10, 2026 | The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthen... |
| CVE-2026-19348 | CRITICAL | 9.8 | 2.5% | Aug 9, 2026 | A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf ... |
| CVE-2026-18473 | CRITICAL | 9.1 | 0.2% | Aug 9, 2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now